PT-2026-3643 · Unknown · Binary-Parser

Keichi

·

Publicado

2026-01-20

·

Atualizado

2026-02-03

·

CVE-2026-1245

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions binary-parser versions prior to 2.3.0
Description A code injection flaw exists in the binary-parser library. This issue allows for arbitrary JavaScript code execution when untrusted values are used in parser field names or encoding parameters. The library directly interpolates these values into dynamically generated code without proper sanitization, enabling attackers to execute code within the Node.js process. The issue is due to the use of the Function constructor with unsanitized input. This could lead to data access, logic manipulation, or system command execution. The vulnerability is also referred to as 'ParserPoison'.
Recommendations Upgrade to binary-parser version 2.3.0 or newer.

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-1245
GHSA-M39P-34QH-RH3W

Produtos afetados

Binary-Parser